2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26200 | MEDIUM | 6.8 | 0.2% | Feb 26, 2021 | A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their... |
| CVE-2020-24455 | MEDIUM | 6.7 | 0.6% | Feb 26, 2021 | Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation ... |
| CVE-2020-4931 | MEDIUM | 6.5 | 1.1% | Feb 24, 2021 | IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to ... |
| CVE-2020-12702 | MEDIUM | 4.6 | 0.3% | Feb 24, 2021 | Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS... |
| CVE-2020-8297 | MEDIUM | 4.3 | 1.3% | Feb 23, 2021 | Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users wit... |
| CVE-2020-7120 | MEDIUM | 5.3 | 0.3% | Feb 23, 2021 | A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior t... |
| CVE-2020-26609 | MEDIUM | 5.4 | 0.9% | Feb 23, 2021 | fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain... |
| CVE-2020-4953 | MEDIUM | 4.3 | 1.1% | Feb 23, 2021 | IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's int... |
| CVE-2020-8902 | MEDIUM | 4.3 | 0.3% | Feb 23, 2021 | Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can u... |
| CVE-2020-13697 | MEDIUM | 6.1 | 0.8% | Feb 23, 2021 | An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic ... |
| CVE-2020-29075 | MEDIUM | 6.5 | 7.8% | Feb 23, 2021 | Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) a... |
| CVE-2020-27819 | MEDIUM | 5.5 | 0.8% | Feb 23, 2021 | An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer derefere... |
| CVE-2020-35852 | MEDIUM | 6.1 | 1.1% | Feb 23, 2021 | Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatb... |
| CVE-2020-36232 | MEDIUM | 5 | 1.0% | Feb 22, 2021 | The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from vers... |
| CVE-2020-29453 | MEDIUM | 5.3 | 23.1% | Feb 22, 2021 | The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 befor... |
| CVE-2020-29448 | MEDIUM | 5.3 | 2.3% | Feb 22, 2021 | The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, ... |
| CVE-2020-22475 | MEDIUM | 6.8 | 0.5% | Feb 22, 2021 | "Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application compo... |
| CVE-2020-22474 | MEDIUM | 6.5 | 1.0% | Feb 22, 2021 | In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local fi... |
| CVE-2020-19762 | MEDIUM | 6.1 | 1.0% | Feb 22, 2021 | Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code vi... |
| CVE-2020-3664 | MEDIUM | 6 | 0.2% | Feb 22, 2021 | Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon ... |
| CVE-2020-11286 | MEDIUM | 6.8 | 0.2% | Feb 22, 2021 | An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard... |
| CVE-2020-11198 | MEDIUM | 6.7 | 0.1% | Feb 22, 2021 | Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improp... |
| CVE-2020-11147 | MEDIUM | 6.7 | 0.2% | Feb 22, 2021 | Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of... |
| CVE-2020-35664 | MEDIUM | 6.1 | 0.7% | Feb 22, 2021 | An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in ... |
| CVE-2020-35571 | MEDIUM | 6.1 | 0.7% | Feb 22, 2021 | An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.ph... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now